Summary
Togoder Security scanned the npm package eth-json-rpc-filters@6.0.1 on Oct 4, 2026. An AI review of 9 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Insecure randomness
NPS-4C48B4C836D5
The function unsafeRandomBytes explicitly uses Math.random() to generate random bytes. Math.random() is not cryptographically secure and its output is predictable. If this function is used for security-sensitive purposes such as generating private keys, nonces, or session tokens, it could lead to vulnerabilities. The naming 'unsafeRandomBytes' suggests awareness, but the presence of such a function in a utility module may encourage misuse.
Weak random number generation for subscription IDs
NPS-C2AFCDE5B054
The code uses unsafeRandomBytes(16) to generate subscription IDs. If unsafeRandomBytes is not cryptographically secure (e.g., uses Math.random or a weak PRNG), it could allow attackers to predict or brute-force subscription IDs, leading to unauthorized access to subscription data or denial of service. The name 'unsafe' suggests it may intentionally use a non-cryptographic source.
Potential unhandled promise rejection / async destroy calls
NPS-B1A11E7315A3
The destroy function calls subscriptions[id].destroy() without awaiting or catching errors. While not a direct security issue, it could lead to resource leaks or unhandled rejections if destroy fails. More importantly, the asynchronous destroy in createSubNewHeads removes a listener, but if the blockTracker emits events during the async gap, it might cause unexpected behavior.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| hexUtils.js | medium | The code provides utility functions for hex and block reference manipulation, but includes an insecure random byte generator using Math.random(), which is cryptographically weak and could be dangerous if misused for security purposes. |
| subscriptionManager.js | medium | The code appears to be a legitimate Ethereum subscription manager, but uses a function named 'unsafeRandomBytes' for generating subscription IDs, which may introduce predictability risks. |
| base-filter-history.js | safe | Cleared by Jev triage; no further analysis needed |
| base-filter.js | safe | Cleared by Jev triage; no further analysis needed |
| block-filter.js | safe | No malicious patterns detected |
| getBlocksForRange.js | safe | No malicious patterns detected; the code performs standard Ethereum JSON-RPC block queries with retry logic and no exfiltration, credential access, obfuscation, or suspicious system operations. |
| index.js | safe | No malicious patterns detected; the code is a legitimate Ethereum JSON-RPC filter middleware implementation. |
| log-filter.js | safe | No malicious patterns detected |
| tx-filter.js | safe | No malicious patterns detected |
Scanned versions of eth-json-rpc-filters
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 6.0.1 | Needs review | 9 | Oct 4, 2026 |
Frequently asked questions
Is eth-json-rpc-filters safe to use?
No confirmed malware was found in eth-json-rpc-filters@6.0.1, but the review flagged 2 medium, 1 low severity findings for risky patterns worth checking before you rely on it.
Does eth-json-rpc-filters contain malware?
No malware was identified in eth-json-rpc-filters@6.0.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was eth-json-rpc-filters checked?
Togoder Security downloaded the published npm package and had an AI model read its 9 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan eth-json-rpc-filters together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in eth-json-rpc-filters@6.0.1, cost nothing.